# Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CWE-74) The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component. **Stack:** JavaScript - Prevalence: Alta Frequentemente explorada - Impact: Alto 3 regras de severidade alta - Prevention: Documentada 3 exemplos de correção **OWASP:** Injection (A03:2021-Injection) - #3 ## Description Software has certain assumptions about what constitutes data and control. Injection problems occur when these assumptions are violated. Attackers exploit this by inserting special characters or instructions that modify the intended interpretation. ## Prevention Estratégias de prevenção para Injection baseadas em 1 regras de detecção do Shoulder. ### JavaScript Use system prompts with strict boundaries, sanitize and limit user input before including in AI prompts ## Warning Signs - [HIGH] user input flowing directly into AI/LLM prompts without sanitization ## Consequences - Executar código não autorizado - Ler dados da aplicação - Modificar dados da aplicação - Burlar mecanismo de proteção ## Mitigations - Use interfaces parametrizadas que separem código de dados - Valide e codifique toda a entrada antes de usá-la em componentes downstream - Use allowlists para validação de entrada sempre que possível ## Detection - Total rules: 3 - Languages: go, javascript, typescript, python ## Rules by Language ### Javascript (1 rules) - **Prompt Injection via Untrusted Input** [HIGH]: Detects user input flowing directly into AI/LLM prompts without sanitization. - Remediation: Use system prompts and sanitize user input with length limits before including in prompts. ```javascript const sanitized = userInput.substring(0, 500); const messages = [ { role: 'system', content: 'Answer only about products.' }, { role: 'user', content: sanitized } ]; ``` Learn more: https://shoulder.dev/learn/javascript/cwe-74/prompt-injection ### Typescript (1 rules) - **Prompt Injection via Untrusted Input** [HIGH]: Detects user input flowing directly into AI/LLM prompts without sanitization. - Remediation: Use system prompts and sanitize user input with length limits before including in prompts. ```javascript const sanitized = userInput.substring(0, 500); const messages = [ { role: 'system', content: 'Answer only about products.' }, { role: 'user', content: sanitized } ]; ``` Learn more: https://shoulder.dev/learn/javascript/cwe-74/prompt-injection